After completing check-out, your download will be available under MyISACA > Resources.
Malicious actors are compromising networks, encrypting data and then offering the decryption keys in exchange for payment. While ransomware attacks involving high-profile enterprises may receive attention in the news, increased reliance on information and technology systems makes individual users and small to medium sized organizations subject to extortion as well. In addition to the financial cost, subjects of extortion also experience business disruption and all of the consequences associated with data exposure.
To minimize the possibility and the impact of a ransomware attack, ISACA is introducing its Ransomware Readiness Audit Program. This audit program provides foundational information, practical guidance, and approaches in preparation and potential recovery from a ransomware related incident. Specifically covered in the audit program are the following:
- Governance – The oversight, guidance and requirements, as defined by governing body as they apply to ransomware incidents and business recovery; this includes not only the appropriate policies and procedures, but also determining the risk of various potential ransomware incidents the organization may face (i.e., commodity, big game hunters)
- Information Protection Processes and Procedures – The operationalization of defined management objectives, inclusive of account inventory & reconciliation, data inventory & backup, data loss prevention, identity management, threat intelligence management, threat modeling, and continuous monitoring.
- Technical Safeguards – These are foundational technologies that are needed to reduce the impact of a ransomware event and include, but not limited to, asset inventory, asset management, network architecture, forensic capabilities, deceptive technologies, intrusion detection/prevention systems, threat intelligence platforms, patch management suites, and centralized monitoring systems
- Human Safeguards – The human element associated with ransomware readiness. From a response/defensive perspectives, these are the various efforts ranging from user awareness & training, how to report suspected events and threats which can result in a ransomware incident. From a readiness/offensive perspective, such efforts as network and systems analytics to threat hunting are discussed.